Cracked surface with glowing orange numbers
Crypto

Balance Coin collapses 99% after reported 42DAO exploit on BNB Chain

Security firms tied the depeg to alleged null-address minting and PancakeSwap V2 swaps into BSC-USD and BTCB.

By AI News Crypto Editorial Team7 min read

Balance Coin (BLC), an algorithmic stablecoin in the Balance Protocol ecosystem, broke its $1 peg and fell more than 99% amid reports of an exploit tied to 42DAO on BNB Chain. Security firms pointed to alleged unauthorized minting from a null address followed by rapid dumping through PancakeSwap V2 as the immediate catalyst.

Key Takeaways

  • Balance Coin traded around $0.001358 after previously sitting near $0.9954, per CoinMarketCap pricing cited in the incident coverage.
  • A reported $915,000 exploit tied to 42DAO was flagged by PeckShield as the driver behind the depeg.
  • TenArmor described two attack transactions on BNB Chain that involved GemJoin and 42DAO.
  • The reported flow included minting 4.5 million BLC from a null address and swapping it on PancakeSwap V2 into Binance-pegged USDT (BSC-USD) and BTCB, followed by a second mint of 5,900 BLC about two hours later.

Balance Coin’s Peg Breaks as Exploit Reports Hit 42DAO

Balance Coin, an algorithmic stablecoin designed to hold a $1 peg, saw that peg effectively fail in one move. The token was cited as trading at about $0.001358 after being around $0.9954, per CoinMarketCap data referenced in the coverage.

The market didn’t treat this as a routine algorithmic wobble. PeckShield tied the depeg to a reported $915,000 exploit involving 42DAO, the DAO that governs the Balance Protocol ecosystem and its BLC token.

What stands out for traders is the speed and magnitude. A >99% collapse is not a slow bleed from drifting incentives. It reads like a liquidity event where sell pressure overwhelms whatever peg assumptions existed, and the reported exploit narrative explains why.

The Alleged Onchain Path: Null-Address Minting and PancakeSwap V2 Dumps

The alleged mechanics matter because they describe a clean, mechanical route from “bug” to “price at fractions of a cent.” The onchain activity described in the report starts with an unauthorized supply increase.

The first leg was described as minting 4.5 million BLC from a null address. In practice, a null address (often 0x000…000) is typically a burn or placeholder destination. Seeing minting sourced from it is a red flag because it implies a critical authorization failure or a mint pathway that should not exist.

From there, the reported flow was straightforward. The minted BLC was sent to PancakeSwap V2 on BNB Chain and swapped into Binance-pegged USDT (BSC-USD) and Binance Bitcoin (BTCB). That’s the classic “mint-then-dump” pattern: create inventory at zero cost, then immediately convert it into assets the attacker can actually keep.

TenArmor also described two attack transactions involving GemJoin and 42DAO on BNB Chain. The second transaction reportedly replicated the exploit about two hours later, minting an additional 5,900 BLC to extract more BSC-USD and BTCB.

Two discrete actions changes how I frame the incident. It suggests either an initial drain followed by a follow-up attempt, or a test-and-repeat pattern where the attacker checks whether the door is still open. The packet does not explain GemJoin’s function in the system, but its appearance in both transactions is a key breadcrumb for anyone trying to map the exploit surface.

Why Unauthorized Minting Can Vaporize an Algorithmic Stablecoin

Algorithmic stablecoins live and die on market confidence and onchain plumbing. They are designed to maintain a target price, often $1, using mechanisms and incentives rather than being fully backed by cash or equivalents.

If the reported exploit vector is accurate, the peg break is the predictable outcome of a supply shock. Minting 4.5 million BLC and routing it into an AMM like PancakeSwap V2 forces the pool to absorb a sudden wave of sell pressure. AMMs don’t “pause to find a fair price.” They reprice against the pool’s reserves, and that repricing can be brutal when the sell size dwarfs available depth.

The second-order effect is reflexive. Once the stablecoin prints far below peg, every holder is incentivized to exit before liquidity deteriorates further. That’s not a moral panic, it’s market structure. The reported $915,000 figure attached to the exploit also matters here. It frames the event as a material security incident, not a minor deviation, and that framing can accelerate risk-off behavior across the ecosystem’s governance and token plumbing.

The assets named in the swaps, BSC-USD and BTCB, also tell you what the attacker wanted: liquid, widely accepted tokens on BNB Chain. That choice is consistent with an exploit monetization path rather than a governance dispute or a slow unwind.

Open Questions: Loss Breakdown, GemJoin’s Role, and Confirmation From 42DAO

This story is still missing the pieces traders typically use to size the blast radius.

First, there is no confirmation in the packet from 42DAO or Balance Protocol about the exploit vector, whether minting has been paused, or whether contracts have been upgraded. Until that exists, the market is trading on security-firm attribution and the reported onchain pattern.

Second, the $915,000 figure is being cited, but the packet does not detail how it was calculated, what pricing source was used, or whether it reflects realized proceeds, pool impact, or a broader accounting of losses.

Third, TenArmor’s note that GemJoin was involved in both attack transactions is important, but its role is not explained here. If GemJoin is a contract that touches mint permissions or collateral logic, it becomes central to remediation. If it is peripheral, it may be an artifact of routing.

Finally, the second reported mint amount, 5,900 BLC, is small relative to 4.5 million BLC. The packet provides no clarification on whether that reflects token denomination, decimals, or simply a smaller follow-up attempt.

What I’m watching next is concrete. Any post-mortem from 42DAO/Balance Protocol that confirms the exploit path and states whether minting has been paused or contracts upgraded will move this from “reported” to “actionable.” I’m also watching for any additional suspicious mints or repeat swap patterns after the reported second attempt two hours later, plus updates from PeckShield or TenArmor that publish transaction hashes, exact timestamps, and a precise breakdown of BSC-USD and BTCB extracted. On the market-structure side, liquidity and pricing behavior for BLC on PancakeSwap V2, including depth changes and pool imbalances, will show whether the dumping pressure is finished or still leaking.

This Looks Like a Mint-Then-Dump Shock, Not a Slow Depeg

I’m treating this as an exploit-driven supply shock until proven otherwise. The reported sequence, minting 4.5 million BLC from a null address and immediately swapping it on PancakeSwap V2 into BSC-USD and BTCB, is the cleanest mechanical explanation for why a token that was near $0.9954 could print around $0.001358.

The two-transaction detail matters. TenArmor described two attack transactions involving GemJoin and 42DAO, and the second attempt reportedly came two hours later with another mint of 5,900 BLC. That pattern is consistent with either a follow-up drain or a check to see if mitigations were in place. In both cases, it argues against a narrative where the peg simply “drifted” due to incentives. This reads like someone manufactured sell pressure.

There are three scenarios I’m mapping from the facts we actually have.

Scenario one is the straightforward one: the exploit vector is confirmed by 42DAO/Balance Protocol, minting is halted or contracts are upgraded, and the onchain pattern stops. In that case, the key confirmation point is the absence of further suspicious mints and repeat PancakeSwap V2 swap patterns after the reported second attempt. The market can still price BLC poorly, but the immediate bleed would be structurally contained.

Scenario two is partial containment: the exploit is real, but the system remains exposed long enough for additional mints and dumps. The confirmation point is simple and onchain. More null-address minting or repeated swap behavior into BSC-USD and BTCB would indicate the door is still open, and liquidity on PancakeSwap V2 would likely continue to skew as reserves get pulled against.

Scenario three is information risk: the exploit narrative is directionally right but the details are wrong or incomplete, including the $915,000 figure and the small second mint amount. The confirmation point here is whether security firms publish transaction hashes, timestamps, and a reconciled breakdown of extracted assets that matches the reported flow. Without that, traders are left with a headline number and a plausible mechanism, which is enough to trigger risk-off but not enough to quantify exposure.

My core thesis is narrow: the reported peg collapse is best explained by unauthorized minting feeding immediate AMM dumping, and it will be confirmed if post-mortem evidence and onchain traces show the mint pathway was real and has stopped producing new BLC supply into PancakeSwap V2 pools.

Sources